Executive brief
Citrix Session Recording is a tool used by organizations to monitor and record user activity in virtual desktop environments for compliance and security auditing. A vulnerability in this software could allow an authorized user on the internal network to execute malicious code on the recording server. This could lead to unauthorized access to sensitive session data or a disruption of the auditing service.
Technical details
A deserialization of untrusted data vulnerability (CWE-502) exists in Citrix Session Recording. The flaw allows an attacker to achieve remote code execution with the privileges of the NetworkService account. Exploitation requires the attacker to be authenticated and located on the same intranet (adjacent network) as the target server. The vulnerability has been observed being exploited in the wild. Citrix has released updates to address this issue, and users are advised to upgrade to version 2407 or the latest cumulative updates for LTSR versions.
Affected products
- Citrix Session Recording Versions before 2407; 1912 LTSR; 2203 LTSR; 2402 LTSR
Timeline
- 2025-08-25: disclosed
- 2025-08-25: kev added: Added to CISA KEV catalog
- 2025-08-25: exploited: Reported as exploited in the wild in CISA KEV catalog